Information security has become a business-critical issue. It is not something you can tackle in isolation, as there are obvious overlaps with cybersecurity and data protection.
A logical process for reviewing and addressing your information security requirements is to:
identify what information you hold, manage or are responsible for
assess the risks to that information
implement systems and controls to protect the information and mitigate risks so far as reasonably practicable
train your staff, which should include ongoing awareness campaigns
review your processes on a recurring basis, at least annually
You must protect client money and assets.
You must also keep the affairs of clients confidential unless disclosure is required or permitted by law or the client consents.
Integrity and confidentiality of personal data is a key principle of Assimilated Regulation (EU) 2016/679, General Data Protection Regulation (UK GDPR). Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. This is also known...
To view the latest version of this document and thousands of others like it, sign-in with LexisNexis or register for a free trial.
**Trials are provided to all LexisNexis content, excluding Practice Compliance, Practice Management and Risk and Compliance, subscription packages are tailored to your specific needs. To discuss trialling these LexisNexis services please email customer service via our online form. Free trials are only available to individuals based in the UK, Ireland and selected UK overseas territories and Caribbean countries. We may terminate this trial at any time or decide not to give a trial, for any reason. Trial includes one question to LexisAsk during the length of the trial.
Law360, London: The Solicitors Disciplinary Tribunal (SDT) said in a first-of-its-kind ruling released on 3 September 2026 that it has banned a...
HMRC has announced that Illumina Cambridge Limited has paid a £7.4 million compound settlement as an alternative to criminal prosecution for breaches...
The Department for Business, Innovation, Science and Trade (BIST), Foreign, Commonwealth & Development Office (FCDO) and Office of Trade Sanctions...
The National Economic Crime Centre (NECC) has published its 2025–26 annual report on the UK-wide response to fraud and illicit finance. It works with...
Priority between loss reliefs in loss making companiesWhy does it matter?A company that is a member of a group and has incurred any of the types of losses available for surrender by way of group relief may, without any further rules, have more than one way in which to use the loss. There are a
Strike out—making an application to strike out a statement of caseA strike out order can be made either following an application by the parties or on the court's own initiative. This Practice Note deals with the scenario of the order being made following a party's application.Making an application
Contributory negligence in personal injury claimsContributory negligence is a partial defence which can lead to a discount in damages.Other defences may also be relevant. See Practice Notes: Did the claimant consent to the risk of injury? and Was the claimant involved in an illegal activity?If a
Template for regulatory references given by SMCR firms and disclosure requirements[Insert addressee details]Dear [insert name][It is our understanding that [insert name of prospective employee] [was an employee of yours between the dates of [insert dates as appropriate] OR is a current employee of
0330 161 1234